Top

Category: Cyber-crime


Cyber-crime, Malware

New variant of BBTok Trojan targets users of +40 banks in LATAM

September 25, 2023

Via: Security Affairs

Check Point researchers warn of a new variant of a banking trojan, called BBTok, that is targeting users of over 40 banks in Latin America. The new malware campaign relies on new infection chains and employs a unique combination of […]


Cyber-crime, Identity theft

TransUnion reckons big dump of stolen customer data came from someone else

September 21, 2023

Via: The Register

Days after a miscreant boasted leaking a 3GB-plus database from TransUnion containing financial information on 58,505 people, the credit-checking agency has claimed the info was actually swiped from a third party. On Sunday, a thief using the handle USDoD shared […]


Cyber warfare, Cyber-crime

International Criminal Court hit in cyber-attack amid Russia war crimes probe

September 20, 2023

Via: The Register

The International Criminal Court said crooks breached its IT systems last week, and that attack isn’t over yet, with the ICC saying the “cybersecurity incident” is still ongoing. In a statement shared via the site formerly known as Twitter, the […]


Cyber-crime, Identity theft

US-Canada water org confirms ‘cybersecurity incident’ after ransomware crew threatens leak

September 15, 2023

Via: The Register

The International Joint Commission, a body that manages water rights along the US-Canada border, has confirmed its IT security was targeted, after a ransomware gang claimed it stole 80GB of data from the organization. “The International Joint Commission has experienced […]


Cyber-crime, Identity theft

Greater Manchester Police ransomware attack another classic demo of supply chain challenges

September 15, 2023

Via: The Register

The UK’s Greater Manchester Police (GMP) has admitted that crooks have got their mitts on some of its data after a third-party supplier responsible for ID badges was attacked. According to the Manchester Evening News the stolen data included the […]


Cyber-crime, Phishing

W3LL Store: How a Secret Phishing Syndicate Targets 8,000+ Microsoft 365 Accounts

September 6, 2023

Via: The Hacker News

A previously undocumented “phishing empire” has been linked to cyber attacks aimed at compromising Microsoft 365 business email accounts over the past six years. “The threat actor created a hidden underground market, named W3LL Store, that served a closed community […]


Cyber warfare, Cyber-crime

Meta Takes Down Thousands of Accounts Involved in Disinformation Ops from China and Russia

September 5, 2023

Via: The Hacker News

Meta has disclosed that it disrupted two of the largest known covert influence operations in the world from China and Russia, blocking thousands of accounts and pages across its platform. “It targeted more than 50 apps, including Facebook, Instagram, X […]


Cyber-crime, Malware, Phishing

New SuperBear Trojan Emerges in Targeted Phishing Attack on South Korean Activists

September 1, 2023

Via: The Hacker News

A new phishing attack likely targeting civil society groups in South Korea has led to the discovery of a novel remote access trojan called SuperBear. The intrusion singled out an unnamed activist, who was contacted in late August 2023 and […]


Cyber-crime, Malware, Mobile, Mobile security

Trojanized Signal, Telegram apps found on Google Play, Samsung Galaxy Store

August 31, 2023

Via: Help Net Security

ESET researchers have identified two active campaigns targeting Android users, where the threat actors behind the tools for Telegram and Signal are attributed to the China-aligned APT group GREF. Most likely active since July 2020 and since July 2022, respectively […]


Cyber-crime, Malware

Cybercriminals Team Up to Upgrade ‘SapphireStealer’ Malware

August 31, 2023

Via: Dark Reading

Cybercriminals are mining the capabilities of an open source infostealer called “SapphireStealer,” developing a legion of variants that are helping to democratize the cybercrime landscape when it comes to carrying out data-theft attacks. Ever since a Russian-language hacker named Roman […]


Cyber warfare, Cyber-crime

Chinese Hacking Group Exploits Barracuda Zero-Day to Target Government, Military, and Telecom

August 29, 2023

Via: The Hacker News

A suspected Chinese-nexus hacking group exploited a recently disclosed zero-day flaw in Barracuda Networks Email Security Gateway (ESG) appliances to breach government, military, defense and aerospace, high-tech industry, and telecom sectors as part of a global espionage campaign. Mandiant, which […]


Cyber warfare, Cyber-crime

China-Linked Flax Typhoon Cyber Espionage Targets Taiwan’s Key Sectors

August 25, 2023

Via: The Hacker News

A nation-state activity group originating from China has been linked to cyber attacks on dozens of organizations in Taiwan as part of a suspected espionage campaign. The Microsoft Threat Intelligence team is tracking the activity under the name Flax Typhoon, […]


Cyber-crime, Malware

New Telegram Bot “Telekopye” Powering Large-scale Phishing Scams from Russia

August 24, 2023

Via: The Hacker News

A new financially motivated operation is leveraging a malicious Telegram bot to help threat actors scam their victims. Dubbed Telekopye, a portmanteau of Telegram and kopye (meaning “spear” in Russian), the toolkit functions as an automated means to create a […]


Cyber-crime, Malware

Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software Updates

August 22, 2023

Via: The Hacker News

A previously undocumented threat cluster has been linked to a software supply chain attack targeting organizations primarily located in Hong Kong and other regions in Asia. The Symantec Threat Hunter Team, part of Broadcom, is tracking the activity under its […]


Cyber-crime, Malware

This Malware Turned Thousands of Hacked Windows and macOS PCs into Proxy Servers

August 21, 2023

Via: The Hacker News

Threat actors are leveraging access to malware-infected Windows and macOS machines to deliver a proxy server application and use them as exit nodes to reroute proxy requests. According to AT&T Alien Labs, the unnamed company that offers the proxy service […]


Cyber-crime, Malware

HiatusRAT Malware Resurfaces: Taiwan Firms and U.S. Military Under Attack

August 21, 2023

Via: The Hacker News

The threat actors behind the HiatusRAT malware have returned from their hiatus with a new wave of reconnaissance and targeting activity aimed at Taiwan-based organizations and a U.S. military procurement system. Besides recompiling malware samples for different architectures, the artifacts […]


Cyber-crime, Malware

Russian Hackers Use Zulip Chat App for Covert C&C in Diplomatic Phishing Attacks

August 17, 2023

Via: The Hacker News

An ongoing campaign targeting ministries of foreign affairs of NATO-aligned countries points to the involvement of Russian threat actors. The phishing attacks feature PDF documents with diplomatic lures, some of which are disguised as coming from Germany, to deliver a […]


Cyber-crime, Malware

Over 120,000 Computers Compromised by Info Stealers Linked to Users of Cybercrime Forums

August 15, 2023

Via: The Hacker News

A “staggering” 120,000 computers infected by stealer malware have credentials associated with cybercrime forums, many of them belonging to malicious actors. The findings come from Hudson Rock, which analyzed data collected from computers compromised between 2018 to 2023. “Hackers around […]


Cyber-crime, Malware

Charming Kitten Targets Iranian Dissidents with Advanced Cyber Attacks

August 14, 2023

Via: The Hacker News

Germany’s Federal Office for the Protection of the Constitution (BfV) has warned of cyber attacks targeting Iranian persons and organizations in the country since the end of 2022. “The cyber attacks were mainly directed against dissident organizations and individuals – […]


Cyber-crime, Phishing

Cybercriminals Increasingly Using EvilProxy Phishing Kit to Target Executives

August 10, 2023

Via: The Hacker News

Threat actors are increasingly using a phishing-as-a-service (PhaaS) toolkit dubbed EvilProxy to pull off account takeover attacks aimed at high-ranking executives at prominent companies. According to Proofpoint, an ongoing hybrid campaign has leveraged the service to target thousands of Microsoft […]